logo

Kinsing targeting cloud servers (Campaign)

ID: fab147a4-efda-52fb-bbb0-27e1757cafa6

STIX ID: report--fab147a4-efda-52fb-bbb0-27e1757cafa6

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-05-16

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers observed Kinsing malware campaigns targeting Linux cloud infrastructure and Apache Tomcat servers; the attackers exploit vulnerabilities to install backdoors and the XMRig Monero miner and hide malicious files in unconventional filesystem locations (e.g., /var/cache/man/cs/cat1/, /var/lib/gssproxy/rcache/) to evade detection. Activity has been ongoing since mid-2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.